Relay Privacy Policy

Effective date: 2026-10-01

Last updated: 2026-10-01

1. Introduction & Scope

This Privacy Policy explains how Martello Systems, LLC ("Martello Systems," "we," "us," or "our") collects, uses, shares, and protects personal information when you use Relay at gorelaycrm.com and related applications and services (the "Service"). It applies to information we process about visitors and Account holders.

This Policy also describes how we handle information about your End Users — the people whose details you (as a business using the Service) import into, collect through, or otherwise submit to the Service, such as your contacts, customers, leads, or subscribers. For that End User information, you are the controller and we act as your processor (or "service provider"/"processor" under applicable law): we handle it on your behalf and under your instructions to provide the Service. You are responsible for having a lawful basis and any required consent to collect and use your End Users' information and to instruct us to process or message it.

By using the Service, you agree to the practices described in this Policy. This Policy is incorporated into and subject to our Terms of Service. If you do not agree with this Policy, please do not use the Service.

2. Information We Collect

1. Account information. When you register, we collect information such as your name, email address, password (stored in hashed form), business name, and team/workspace details you provide.

2. Customer Data you provide. We collect and store the information you enter or import to run your business through the Service, including any personal information about your End Users — for example names, email addresses, phone numbers, companies, notes, records, and form or intake submissions.

3. Communications content. Where the Service sends or receives email, SMS/text, voice, or other communications on your behalf, we process the content of those communications along with related metadata (timestamps, delivery status, opt-out status) so we can deliver, organize, and display them for you.

4. Payment information. Subscription payments are processed by a third-party payment processor (for example, Stripe, Inc.). We do not collect or store your full payment card numbers. The payment processor processes your payment details directly; we receive limited information such as a transaction identifier, the last four digits and card brand, subscription status, and billing metadata.

5. Usage, device, and log data. We automatically collect information such as IP address, browser and device type, pages and features used, referring URLs, timestamps, and diagnostic/log data.

6. Cookies and similar technologies. We use cookies and similar technologies as described in Section 8.

7. Communications with us. If you contact us (for example, at [email protected]), we collect the content of your messages and our correspondence.

We do not intentionally collect sensitive categories of personal information beyond what is needed to provide the Service, and we ask that you not submit sensitive information (such as government ID numbers, health data, or precise geolocation of End Users) unless a product-specific addendum expressly addresses that category.

3. How We Use Information

We use personal information to: provide, operate, and maintain the Service and your Account; store and organize your Customer Data; run the Automations and campaigns you configure; send and receive the communications you direct; provide AI-assisted features that draft, summarize, or analyze content at your request; process subscriptions, billing, and payments; send transactional and account communications to you; provide customer support; monitor, secure, debug, and improve the Service; detect and prevent fraud, abuse, and security issues; and comply with legal obligations and enforce our agreements. We do not sell your personal information, and we do not use your End Users' personal information for our own marketing.

4. Legal Bases for Processing (GDPR/UK GDPR)

Where the GDPR or UK GDPR applies, we process personal information on the following bases: performance of a contract (to provide the Service and process your Subscription); legitimate interests (to secure, improve, and analyze the Service and prevent fraud and abuse, balanced against your rights and freedoms); consent (for optional communications and certain non-essential cookies, which you may withdraw at any time); and legal obligation (to comply with applicable law, including tax and recordkeeping requirements). For personal information about your End Users, you are responsible for establishing the legal basis for collecting and using it and for instructing us to process it; we process it as your processor on your documented instructions.

5. How We Share Information

We share personal information only as described below. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

1. Service providers / sub-processors. We use a limited set of third-party service providers to operate the Service, engaged as our sub-processors and bound by appropriate confidentiality and data-protection terms. These fall into the following categories: cloud infrastructure and hosting; database and file storage; payment processing and subscription billing; email delivery; SMS and voice delivery; calendar and sign-in providers you connect an account with; DNS lookup services used to verify sending domains; and AI/model providers, which receive the content described in Section 6. We do not currently use any third-party analytics, advertising, or product-telemetry provider, and the Service loads no analytics or tracking script. On the canonical Relay service, our current sub-processors in these categories are Anthropic, PBC (AI models, reached through a gateway operated by Martello Systems), Twilio (SMS and voice), Vapi (the real-time voice platform behind the AI Front Desk, which carries and records call audio), Deepgram (speech-to-text transcription of that call audio), Brevo (email delivery), Stripe (payments and subscription billing), Google (calendar sync, Google Sign-In, web fonts, and push notifications to the Relay Android app — the device token for your phone, together with the title and preview text of the notification, is sent to Firebase Cloud Messaging for delivery to that phone), Apple (push notifications to the Relay iPhone app — the device token for your phone, together with the title and preview text of the notification, is sent to the Apple Push Notification service for delivery to that phone), Cloudflare (DNS lookups used to verify sending domains; the edge that serves a workspace's own web address once it verifies one — only that hostname is registered with Cloudflare; Turnstile, the invisible check on a workspace's public forms that a visitor is a person — the visitor's browser loads it from Cloudflare, and the resulting check token and the visitor's IP address are sent to Cloudflare to confirm it; and R2 object storage, where the files uploaded to or received by a workspace — form attachments, contact and company files, logos, message attachments and uploaded knowledge documents — are stored in a private bucket that is never exposed directly; Relay itself serves each file, to your signed-in team or through a link you chose to share, such as a public form's logo or a shared sales document), Meta Platforms (Facebook and Instagram — when you connect a Page, the text of replies sent to your customers on those networks is transmitted to Meta through the same gateway, on your behalf), Martello Systems, LLC itself (the keys gateway and the Mycel knowledge spine that route or ground the above), and our hosting/infrastructure providers. If you connect an optional integration yourself — for example Square for payments, a mailbox of your own over IMAP/SMTP, or a WhatsApp Business or Facebook Messenger channel through Meta — that provider also receives the data needed to carry out what you connected it for. Automations, webhook subscriptions and connectors you build can also send record data to any endpoint you point them at; there you choose the recipient, not us.

2. At your direction. When you send a message, run an Automation, or connect an integration, we share the necessary information with the relevant provider (for example, sending an End User's phone number to our SMS provider to deliver a message you sent) to carry out your instruction.

3. Legal and safety. We may disclose information if required by law or legal process, or to protect the rights, property, or safety of Martello Systems, our users, or others, or to enforce our Terms.

4. Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred as part of that transaction, subject to this Policy.

5. Reseller or partner billing relationship. If you were referred to, or purchase, the Service through a reseller, agency, or channel partner, limited account and billing information may be shared with that party to administer your relationship with them, as described at the point of purchase.

6. AI Features — What We Send, and What the AI Can Do

The Service is AI-native, so this Section describes the AI processing specifically rather than leaving it inside the general categories above.

What is sent to our AI provider. To produce an AI result, we send the relevant records to a third-party AI model provider. Depending on the feature you use, that can include: the content of an inbound or outbound message and the recent messages in that conversation; a full conversation thread when you ask for a summary; contact details such as name, email address, phone number, company, tags, lifecycle stage and lead score; deal titles, values, stages, recent activity and the text of notes on a record; real open slots and calendar names when a scheduling question is asked; call transcripts and call summaries; review text, rating and reviewer name; documents and files you add to the knowledge base; form and campaign copy you ask us to draft or improve; and, if you build an Automation with an AI step, whatever record that step is configured to act on. On the canonical Relay service our AI provider is Anthropic, PBC (Claude models). Relay does not hold an Anthropic key directly; these requests are proxied through a gateway operated by Martello Systems, LLC, which sees the same content in transit. If you use the AI Front Desk to answer calls, the phone conversation additionally passes through Vapi (the real-time voice platform, which also synthesizes the agent's speech) and Deepgram (speech-to-text), and what the caller says is transcribed before it reaches the AI model.

One AI step is not optional today. When a message arrives from one of your End Users, its content and the recent messages in that thread are sent to the AI provider to classify intent and sentiment, so the Service can route, tag and escalate it. This classification runs on every inbound message and is not switched off by the AI reply settings, which govern whether the Service replies, not whether it classifies. If you do not want inbound message content processed this way, do not route that channel through the Service.

How it is used. Records are sent to produce your result and are not used to train the AI provider's models or anyone else's, and are not used to build a profile of you or your End Users. AI features run only on your own Account's records, never another customer's.

The AI can take actions, not only suggest. Where you turn it on:

1. The assistant changes records directly. Within a session, and only inside the permission scopes you grant it, the assistant can update a contact field, add a note, move a deal to another stage, and tag fewer than ten contacts at a time. These run immediately, without a separate approval step.

2. Higher-impact actions are held for your approval. Booking, rescheduling or canceling an appointment, enabling or pausing an Automation, tagging ten or more contacts at once, sending a message, merging contacts, and the other gated operations are proposed by the assistant and do not run until a human on your team approves them in the session. This group also includes a small number of narrower removals — taking a tag off a contact, removing a task or a line item from a deal, removing a label or a participant from a conversation, removing an alternate email or phone from a contact, deleting a pipeline goal, clearing an Automation's schedule, and deleting one of your own business objects: a text blast, an email campaign, a saved audience segment, an email template, a saved reply, an unpaid invoice, an order, a product from your price list, a subscription record, a form, an invitation nobody has accepted, a follow-up sequence or one step within it, or the link between two related records. It also includes taking one contact out of a follow-up sequence, which stops them receiving any further step, and two cancellations that use the same word without removing anything: stopping a bulk AI run that is still going, and canceling a social post you have scheduled but not yet published. An unapproved request expires after 24 hours instead of running.

3. The destructive operations are withheld from the AI entirely. Deleting a contact, a company, a deal, a pipeline, a stage, a tag, a calendar, an Automation, a file, or an account is not offered to the assistant at all — it is not told those operations exist, so it cannot propose them and you cannot approve one. The removals it *can* reach are the narrow, reversible ones listed in item 2, and every one of them still needs a human approval.

Two further operations are withheld for a different reason: the assistant cannot lift a do-not-contact and cannot un-suppress an email address. It can add either one, so a person who asks to be left alone can be recorded as such immediately; putting them back into the sendable pool is a decision only a human on your team can take.

4. AI auto-reply can send real messages. Auto-reply is off by default and is set per channel. On "suggest drafts" a person still sends. On the fully automatic setting, a reply is sent to your End User without anyone reading it first. Opt-outs, open escalations, and the master pause are always respected.

5. AI booking is approval-gated by default. If you change that setting to automatic, the assistant can create a real appointment on your calendar on its own.

6. The assistant can work with money, and cannot take any. With the Invoices & payments permission scope granted — it is off by default — the assistant can read what customers owe and have paid, draft an invoice, estimate or quote, email an invoice to the customer it is for, record a payment you have already received by cash, cheque or transfer, and cancel or pause a recurring subscription. Every one of those is held for your approval.

It cannot start or increase a charge, and it cannot touch a card. Creating a card charge, confirming one, issuing a refund, starting or resuming a subscription, and changing what a subscription bills are not offered to it at all. Neither is saving, listing, removing or charging a card on file — card data is never handed to the AI, in either direction. Stopping a charge is available to it; starting one is not, and that asymmetry is deliberate.

7. The assistant can put you on a call, and cannot call anyone on its own. Placing a call rings you first and connects the other person once you pick up, so a human is on the line for the whole call. It has no way to dial someone and play them a recording — those options exist in the underlying feature and are not offered to the assistant at all.

8. The assistant cannot give anyone access to your Account, or take it away. Creating a user, inviting one, removing one, changing a password, sending a password reset, and creating, reading or revoking an API key are not offered to it — it is not told those operations exist. It can read who is on your team, and it can revoke an invitation nobody has accepted yet. This is deliberately stricter than "held for your approval": an approval is a person, and a person can see the consequence of a message being sent, but a request to add a new administrator can arrive inside text the assistant read from an End User and look identical to one you asked for.

9. The assistant can stage a message to many End Users at once, and cannot send one without you. With the Campaigns permission scope granted — it is off by default, and a session that does not request it cannot reach any of this — the assistant can draft a text blast or an email campaign, choose its audience, and count who that audience actually contains. Staging reaches nobody. Sending is a separate step that always requires a human approval, on every campaign, with no automatic setting anywhere that removes it. Opt-outs and email suppression are applied to every recipient at send time, whoever staged the campaign.

Your controls. AI reply behavior, the master pause, and which knowledge folders the AI may draw on are in the AI area of the Service; the assistant's permission scopes are set per session on the Agent screen; pending approvals are shown there for a human to approve or reject. Turning a feature off stops the processing itself, not merely the output.

7. International Data Transfers

We are based in the United States, and the Service is operated from and primarily processes data in the United States. If you or your End Users are located outside the United States, your information will be transferred to, stored, and processed in the United States and possibly other countries where our sub-processors operate, where data-protection laws may differ from those in your country. Where required by applicable law (for example, for transfers of personal information out of the EEA, UK, or Switzerland), we and our sub-processors rely on appropriate safeguards, such as Standard Contractual Clauses or an equivalent legal transfer mechanism, and take steps designed to ensure your information receives an adequate level of protection. By using the Service, you consent to this transfer and processing, subject to this Policy and applicable law.

8. Cookies & Analytics

We use strictly necessary cookies and similar browser storage to keep you logged in, secure your session, and remember your preferences — these are always active because the Service cannot function without them. We do not currently run any third-party analytics or product-telemetry script, and we set no non-essential cookies, which is why you are not shown a cookie-consent banner. We do not use advertising cookies and do not use cookies to sell your data or track you across unrelated websites for advertising. If we ever add consent-gated analytics, we will update this Section and gate it behind a banner before it loads. Your browser does fetch our web fonts from Google's font CDN, which means Google receives your IP address and browser type on page load; no cookie is set by that request. You can control cookies through your browser settings; disabling some may affect functionality.

9. Data Retention

We retain personal information for as long as your Account is active and as needed to provide the Service, then for a reasonable period afterward to comply with legal, tax, accounting, and recordkeeping obligations, resolve disputes, and enforce our agreements. We also retain opt-out and suppression records as needed to honor unsubscribe and STOP requests. When information is no longer needed, we delete or anonymize it. You may request deletion as described in Section 11; certain records (such as billing records) may be retained where required by law, and some information may persist for a limited period in routine backups before being overwritten on their normal cycle.

Call recordings and transcripts. Where the Service places or answers phone calls on your behalf, call audio and a written transcript of the call are recorded and retained, and this applies to both call paths: calls handled by the AI Front Desk, where audio and transcripts are held by our voice platform sub-processor, and calls carried over our telephony provider, where recording may already have been enabled on your account. Retention: the transcripts and summaries we hold, and the audio held by those sub-processors, are kept until deletion — there is no automatic time limit, and we do not currently expire call data on a schedule. They are stored separately from contacts and conversations, so deleting one of those records does not by itself delete the call. Deletion is automated: when your account or workspace is deleted, the call records we hold (transcripts, summaries, recording links) are destroyed in the same run, recordings held by our telephony provider are deleted through its API automatically, and a data-deletion request for the audio and call data held by our voice platform is sent to that provider automatically. Once that request is sent, the voice platform carries out the deletion on its own systems. Call data can also be deleted on its own, without closing your account — see our [Data Deletion](gorelaycrm.com/data-deletion) page. All of this is subject to the same legal-retention and backup-cycle exceptions above. Recording of AI Front Desk calls can be turned off for your account — contact us and we will disable it, after which new calls produce a transcript only. Laws in some jurisdictions require that every party to a call be told it is being recorded. When recording is enabled, the AI Front Desk states that the call is recorded in its opening greeting; you remain responsible for whether that notice is sufficient where you and your callers are located.

10. Security

We use reasonable administrative, technical, and organizational measures designed to protect personal information, including encryption in transit, hashed passwords, encryption of sensitive stored credentials, access controls, and reputable infrastructure and payment providers. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your Account credentials confidential. If we become aware of a breach affecting your personal information, we will notify you and applicable authorities as required by law.

11. Your Privacy Rights

Depending on where you live, you may have rights to: access a copy of the personal information we hold about you; correct inaccurate information; delete your personal information; port/export your data; object to or restrict certain processing; withdraw consent where processing is based on consent; and non-discrimination for exercising your rights.

California residents (CCPA/CPRA). You have the right to know what personal information we collect, access, correct, and delete it, and to opt out of any "sale" or "sharing" of personal information — note that we do not sell or share personal information as those terms are defined under California law, so there is generally nothing to opt out of, but we will honor a request if you make one. You also have the right not to be discriminated against for exercising your rights.

EEA/UK/Swiss residents (GDPR/UK GDPR). You have the rights listed above and the right to lodge a complaint with your local data protection supervisory authority.

Other U.S. state privacy laws. If another applicable U.S. state privacy law grants you rights similar to those above, we will honor requests to exercise those rights in accordance with that law.

If your request concerns information that one of our business customers controls (for example, you are an End User of a business that uses Relay), please contact that business directly; we will assist them as their processor where appropriate and as required by law. To exercise any right with us directly, email [email protected]. We will verify your request and respond within the timeframes required by applicable law.

12. SMS / Phone Data Handling

Where the Service supports SMS or voice communications, phone numbers and messaging content are processed to deliver the communications the relevant business directs. We share a recipient's phone number with our SMS/voice provider only to deliver the messages and calls sent through the Service, and we maintain opt-out and suppression records to honor STOP requests. We do not sell phone numbers, and mobile opt-in/opt-out data collected through the Service is not shared with third parties for their own marketing purposes. Message frequency depends on usage, and message and data rates may apply to recipients per their carrier plans. See any SMS/Messaging Policy posted alongside this Policy for further detail.

13. Children's Privacy

The Service is intended for business users who are at least 18 years old (or such other minimum age as stated in a product-specific addendum) and is not directed to children. We do not knowingly collect personal information from anyone under 13 (or, where a product-specific addendum sets a different threshold consistent with applicable law, that threshold — for example, some products require parental consent for users between 13 and 16). If we learn that we have collected personal information from a child in violation of this Section, we will delete it. If you believe a minor has provided us information, contact [email protected].

14. Third-Party Links & Services

The Service may contain links to, or integrate with, third-party websites, platforms, and services that we do not control. This Policy does not apply to those third parties. We encourage you to review the privacy practices of any third-party site or service before providing it with information.

15. Automated Decision-Making

We do not use your personal information, or your End Users' personal information, to make decisions that produce legal or similarly significant effects concerning you or them without human involvement.

AI-assisted features are not all review-first. Many of them — summaries, scores, suggested replies, drafted copy — produce output for you to review, and you decide whether to act on it. But where you have enabled them, the assistant and AI auto-reply also act: they can change records in your Account, and they can send a message to one of your End Users or book an appointment without a person reading it first. Section 6 sets out exactly which actions run immediately, which are held for a human approval, and which are withheld from the AI entirely, together with the settings that switch each of them off.

16. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and may provide additional notice (for example, by email or an in-product notice). Your continued use of the Service after the changes take effect constitutes acceptance of the updated Policy.

17. Contact

If you have questions or requests regarding this Privacy Policy or your personal information, contact Martello Systems, LLC — Relay, at [email protected] (gorelaycrm.com).